Skip to main content

What the service does

The id service answers two questions for every other service: who is this, and what have they agreed to let you know?

The shape

apps/id/
  app/                  the pages people see, and the REST API (app/api)
  pages/api/oidc/       the OpenID Connect endpoints, served by oidc-provider
  lib/server/           everything that runs on the server
  lib/api/              the API's schemas, shared with the pages
  drizzle/              database migrations, forward and back
  policies/             authorization as Rego
  test/  e2e/           unit tests (vitest) and browser tests (Playwright)

What each piece does

  • Signing in — a passkey, or a code and link by email; new accounts are made by proving an email address.
  • What people share — a consent screen per service, sensitive scopes never ticked for the person, and an account page to take it back.
  • Services — every service that signs in is a group of FG_ID_SERVICE_<NAME>_* variables.
  • Claims from other services — a service can own a scope, and is asked for its claims each time someone shares them.
  • Policy — every authorization decision in one place, as Rego if you like, with reasons shown to the person.
  • Keys — token signing keys and cookie secrets that rotate by themselves.
  • Database — Drizzle over any Postgres, with migrations you can roll back.
  • Deploying — Vercel and Neon, a monolith, and white-labelling.
  • Testing — unit and browser tests that need nothing outside this repository.

What it does not do

It does not keep profiles. A person's nickname, their membership, their preferences belong to the service they are about — the members service keeps membership, and hands it on through claims reviews.